EIP-2026-110005

PRE-CVE

N_CMS 1.1E - Local File Inclusion / Remote Code

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110005. PoCs published by TecR0c.

AI-analyzed exploit summary This exploit targets a Local File Inclusion (LFI) vulnerability in N'CMS 1.1E, leveraging path traversal to include arbitrary files and achieve Remote Code Execution (RCE) by injecting a PHP payload into the database. It includes functionality for user registration, authentication, and command execution via a webshell.

Description

N_CMS 1.1E - Local File Inclusion / Remote Code

Exploits (1)

exploitdb WORKING POC VERIFIED
by TecR0c · pythonwebappsphp
https://www.exploit-db.com/exploits/16961

This exploit targets a Local File Inclusion (LFI) vulnerability in N'CMS 1.1E, leveraging path traversal to include arbitrary files and achieve Remote Code Execution (RCE) by injecting a PHP payload into the database. It includes functionality for user registration, authentication, and command execution via a webshell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: N'CMS 1.1E
Auth required
Prerequisites: PHP.ini with gpc_magic_quotes = Off · Access to the target web application · Valid credentials or ability to register a user
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026